Vulnerabilities > Cloudfoundry

DATE CVE VULNERABILITY TITLE RISK
2017-05-25 CVE-2015-3191 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the change_email form in UAA is vulnerable to a CSRF attack.
6.8
2017-05-25 CVE-2015-3190 Open Redirect vulnerability in multiple products
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which allows an attacker to insert malicious web page as a redirect parameter.
5.8
2017-05-25 CVE-2015-3189 Weak Password Recovery Mechanism for Forgotten Password vulnerability in multiple products
With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a new one.
4.3
2017-05-25 CVE-2015-1834 Path Traversal vulnerability in multiple products
A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release versions prior to v208 and Pivotal Cloud Foundry Elastic Runtime versions prior to 1.4.2.
network
low complexity
cloudfoundry pivotal-software CWE-22
4.0
2017-04-20 CVE-2017-4969 Unspecified vulnerability in Cloudfoundry Cf-Release
The Cloud Controller in Cloud Foundry cf-release versions prior to v255 allows authenticated developer users to exceed memory and disk quotas for tasks.
network
low complexity
cloudfoundry
6.8
2017-04-11 CVE-2016-4468 SQL Injection vulnerability in multiple products
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime before 1.6.29 and 1.7.x before 1.7.7; and Ops Manager 1.7.x before 1.7.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
pivotal-software cloudfoundry CWE-89
8.8
2017-04-06 CVE-2017-4964 Code Injection vulnerability in Cloudfoundry Bosh Azure CPI 22
Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the director, aka a "CPI code injection vulnerability."
local
low complexity
cloudfoundry CWE-94
4.6
2017-03-10 CVE-2017-4960 An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26.
network
low complexity
pivotal-software cloudfoundry
5.0
2017-01-13 CVE-2016-9882 Information Exposure Through Log Files vulnerability in Cloudfoundry Capi-Release and Cf-Release
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0.
network
low complexity
cloudfoundry CWE-532
5.0
2016-12-23 CVE-2016-6659 Improper Authentication vulnerability in multiple products
Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.
network
high complexity
cloudfoundry pivotal-software CWE-287
2.6